> Markdown version of [/jobs/ext/2469766-platform-architect-agentic-trust](https://www.wearedevelopers.com/jobs/ext/2469766-platform-architect-agentic-trust). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Platform Architect - Agentic Trust - **Company:** Entrust Corporation - **Location:** UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, User Authentication, Microsoft Azure, Cyber Security, Federal Information Processing Standards (FIPS), OAuth, Public Key Infrastructure, Management of Software Versions, Google Cloud, Information Technology - **Published:** August 12, 2026 - **Apply:** https://eu.experteer.com/career/view-jobs/platform-architect-agentic-trust-united-kingdom-58914023 ## About the Role with attestation, binding to Entrust roots/HSM) * Own the Permission Slip framework and its cross-boundary exchanges * Oversee the Evidence Ledger and Replay architecture for verifiable records * Own the Policy Engine, MCP Gateway, and Just-in-Time Authorization across planes * Oversee Continuous Authentication, content provenance (C2PA signing), and related governance * Establish frameworks for responsible AI, model governance, and explainability * Partner with business leaders to identify high-value agentic use cases * Ensure solutions meet security, compliance, scalability, and regulatory standards * Chair Architecture Review Board and Boundary Review forum; communicate with executive leadership * Lead technology strategy, vendor diligence, and cross-functional collaboration Tasks * Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field * 15+ years of progressive technology leadership experience * 7+ years leading enterprise architecture aaaaaa * or platform/security architecture for identity, cryptography, or trust infrastructure products * Deep expertise in cryptography and PKI (CAs, key lifecycle, HSMs, signing services, hardware roots of trust) * Experience with workload identity (SPIFFE/SPIRE, SVID, mutual TLS) and modern delegated authorization (OAuth 2.x, token exchange, externalized policy, PBAC/ABAC) * Proven track record designing tamper-evident/append-only verifiable systems (Merkle logs, Certificate Transparency) * Deep expertise in cloud platforms (Azure, AWS, GCP), including confidential computing and external/customer-managed KMS * Experience shipping products under third-party assurance regimes (FIPS 140-3, Common Criteria, eIDAS, SOC 2, FedRAMP) * Proven ability to influence executive stakeholders and drive strategic decisions * Experience leading cross-functional teams in global organizations Key requirements * health and well-being programs * generous 401(k) matching * paid time off and holidays * par·ental a aaL_ * education reimbursement * professional development opportunities ## Description Experteer Overview As Platform Architect for Entrust Agentic Trust, you define and govern the four-plane reference architecture to enable multiple product teams to operate within a cohesive, scalable trust layer. You partner with executives and engineers to ensure secure, compliant, and interpretable identity and authorization infrastructure. You will shape AI-driven decision making with governance and standards that support enterprise agility and safety. This role offers the chance to influence industry standards and drive a trusted, enterprise-wide platform. Pay / Benefits * Define and maintain the four-plane architecture strategy and roadmap across product lines * Set architectural principles, standards, patterns, and governance processes, including boundary arbitration * Own LOB dependency contracts (interfaces, SLAs, versioning, internal transfer-pricing) * Serve as design authority and gate on Agentic Trust Layer build tracks * Own Agent Passport specifications (SPIFFE/SPIRE, SVID, attestation, binding to Entrust roots/HSM) * Own the Permission Slip framework and its cross-boundary exchanges * Oversee the Evidence Ledger and Replay architecture for verifiable records * Own the Policy Engine, MCP Gateway, and Just-in-Time Authorization across planes * Oversee Continuous Authentication, content provenance (C2PA signing), and related governance * Establish frameworks for responsible AI, model governance, and explainability * Partner with business leaders to identify high-value agentic use cases * Ensure solutions meet security, compliance, scalability, and regulatory standards * Chair Architecture Review Board and Boundary Review forum; communicate with executive leadership * Lead technology strategy, vendor diligence, and cross-functional collaboration Tasks * Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field * 15+ years of progressive technology leadership experience * 7+ years leading enterprise architecture programs or platform/security architecture for identity, cryptography, or trust infrastructure products * Deep expertise in cryptography and PKI (CAs, key lifecycle, HSMs, signing services, hardware roots of trust) * Experience with workload identity (SPIFFE/SPIRE, SVID, mutual TLS) and modern delegated authorization (OAuth 2.x, token exchange, externalized policy, PBAC/ABAC) * Proven track record designing tamper-evident/append-only verifiable systems (Merkle logs, Certificate Transparency) * Deep expertise in cloud platforms (Azure, AWS, GCP), including confidential computing and external/customer-managed KMS * Experience shipping products under third-party assurance regimes (FIPS 140-3, Common Criteria, eIDAS, SOC 2, FedRAMP) * Proven ability to influence executive stakeholders and drive strategic decisions * Experience leading cross-functional teams in global organizations Key requirements * health and well-being programs * generous 401(k) matching * paid time off and holidays * par·ental leave * education reimbursement * professional development opportunities ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [The Missing Layer Between Enterprise Data and AI Agents](https://www.wearedevelopers.com/videos/100286-the-missing-layer-between-enterprise-data-and-ai-agents) ## Related Articles - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)